Deployable where every screenshot tool on the market is banned.
Your country sets lawful defaults before a single thing is captured, and an unlawful configuration is blocked in the product — with a reason — not disclaimed in a contract. Compliance profiles can only ever narrow what's collected.
Subtractive by design — a profile can only take capture away.
Set a profile at the workspace level and no admin action inside it can re-enable what it disabled. Attempting to returns a specific error naming the profile and the rule.
GDPR-safe
Free on every plan. The cheapest possible wedge into Europe — WorkTime gates the equivalent behind its top tier.
- Screenshots ≤ 4/hr with forced blur
- Domain-only URLs, no search queries
- Silent Mode blocked
- Disclosure + consent mandatory
- Capture window can never be 'always'
HIPAA-safe
For healthcare estates. A genuinely non-invasive profile, with a BAA available on Enterprise.
- Screenshots off
- Webcam off
- No URL capture, no window titles
- Silent Mode blocked
- Audit log mandatory
GLBA-safe
For financial-services estates that need score-only visibility without media.
- Screenshots off
- Webcam off
- Domain-only URLs
- Silent Mode blocked
- Audit log mandatory
Transparency parity
Whatever an employer can see about a person, that person can see about themselves — in the same detail, for the same period. Every report a manager runs about a member, the member can run about themselves.
A manager can see something a member cannot only under a named, time-boxed exception (max 30 days), opened by an Owner with a reason, written to the audit log, and only where the region permits it. It exists for genuine investigations — it is not a general setting.
What we never collect
Hard product constraints — never shippable, on any plan, in any region:
- Keystroke content, clipboard or message bodies
- Microphone or any audio
- Continuous video or screen recording
- OCR or content indexing of screenshots
- Location, GPS or geofence data — on any platform
- Office-vs-remote inference from IP address
- Any monetary value — no rates, amounts or deductions
- Attendance status or comparison to an expected day
Your jurisdiction sets the guardrails before setup completes.
Region drives the policy template, retention limits and available modes — shown in plain language before anything is captured. A sample of the rulesets that ship in the first release:
EU / EEA (GDPR)
GDPR-safe profile: screenshot cap + forced blur, no search queries, no Silent Mode, mandatory disclosure and consent record.
Germany (BetrVG)
Automatic Mode requires a works-agreement reference; a Works Council Pack exports everything a Betriebsrat asks for.
UK (ICO)
A DPIA is generated, pre-filled from your actual policy.
US notice states (CT, NY, DE)
Disclosure and consent are enforced, and capture is blocked until acknowledged.
Illinois (BIPA)
Webcam or biometric capture is blocked without a stored written consent record.
Australia (NSW/ACT)
A 14-day activation delay and disclosure are enforced; Silent Mode is blocked.
Retention & deletion receipts
Media and activity age out on a plan-set schedule; time entries, notes and projects are kept. We delete when we say we will — and issue a signed receipt in the privacy register proving it.
- Solo14 days
- Starter90 days
- Business12 months
- EnterpriseCustom + BYO storage
Data residency & BYO storage
On Enterprise, keep data in your region and bring your own storage. Screenshots are downscaled and perceptually de-duplicated; score-only workspaces store no media at all.
Audit & governance
Every privileged action — a live-view session, a webcam enable, a policy change, an export — is logged with actor, IP, reason and before/after. Sensitive actions require a written reason and an acknowledgement.
A rollout kit ships with the software: disclosure notices, an employee FAQ, a DPIA generator, a Legitimate Interest Assessment and a Works Council Pack.